Free guide: How to use AI in compliance
Illustration of a hand holding a phone with an identity profile beside a padlock, shield and magnifying glass, representing remote identity verification checks.

The HKMA's September 2026 circular replaces its 2019 remote onboarding rules, names deepfakes and asks banks and SVF licensees to review eKYC. What changes.

Table of contents

The HKMA remote onboarding circular of 3 September 2026 replaces Hong Kong's 2019 and 2021 guidance and asks every authorized institution and stored value facility licensee to review its remote onboarding systems. It names deepfakes as a driver of impersonation and mule-account risk, keeps two core principles, expects continual recalibration and cites tiered account limits as an example.

  • The Hong Kong Monetary Authority issued "Remote on-boarding of individual customers" on 3 September 2026, signed by Raymond Chan, Executive Director (Enforcement and AML).
  • It supersedes the circulars of 1 February 2019 and 24 May 2021 (on iAM Smart), and now covers stored value facility licensees as well as authorized institutions.
  • The two core principles, identity authentication and identity matching, stay; the 2019 technology examples (hologram checks, facial recognition, liveness) are gone.
  • Firms are expected to run a comprehensive review of their solutions, using fraud intelligence shared by the HKMA and the Hong Kong Police Force. The HKMA remote onboarding circular sets no deadline.
  • The HKMA remote onboarding circular is supervisory guidance, not new law: the binding duties remain mainly in Schedule 2 of the Anti-Money Laundering and Counter-Terrorist Financing Ordinance.

What did the HKMA remote onboarding circular change?

The HKMA remote onboarding circular updates regulatory expectations for opening accounts for individuals entirely online. It replaces two earlier letters, extends the audience to stored value facility (SVF) licensees, and explains why: remote channels are now core AML/CFT controls, while AI-driven automation and deepfakes have raised impersonation and mule-account risk.

The circular is two pages long. It says artificial intelligence driven automation and deepfake technology "have increased the potential for impersonation, online fraud and associated mule-account networks at much greater scale." The UK FCA has separately run a money mule accounts review. Two earlier letters remain in force and must be read with it: the 24 September 2020 circular on remote onboarding of corporate customers and the 3 June 2020 feedback from thematic reviews of remote onboarding controls.

Firms must keep meeting two core principles, identity authentication and identity matching, and keep their solutions under "a continual program of updates and recalibration." They should also design products on a risk-based approach proportionate to each customer's assessed money laundering and terrorist financing (ML/TF) risk, and conduct a comprehensive review of their solutions and the oversight around them.

ItemDetail
IssuerHong Kong Monetary Authority, Enforcement and AML
Date3 September 2026
AddresseesAll authorized institutions and SVF licensees
SupersedesCirculars of 1 February 2019 and 24 May 2021
Still applicableCirculars of 3 June 2020 and 24 September 2020
Legal statusSupervisory circular; underlying duties in AMLO Schedule 2
Deadline for the reviewNone stated

How do identity authentication and identity matching work now?

The two principles are unchanged in substance. Identity authentication means ensuring the document, data or information used to verify identity is reliable, including by using technology to check the identity document is genuine. Identity matching means using appropriate technology to "link the customer incontrovertibly to the identity provided." What changed is the guidance around them: no named techniques, no face-to-face benchmark, and an expectation of continual recalibration.

The 2019 circular gave concrete examples: hologram detection and checks on document security features for authentication, and biometric solutions such as facial recognition and liveness detection for matching. It also set a benchmark: remote technology should be at least as robust as checks done with the customer in front of staff. The 2026 text drops the examples and that benchmark sentence. The 2019 letter had already called its examples "illustrative" and "non-exhaustive", so the change is one of emphasis: no technique is named at all. In their place, the circular expects continuous recalibration against the fraud tactics the HKMA and police share with the industry.

A list of techniques ages fast, and face matching with liveness is the step a deepfake is built to defeat. With no technique named, no firm can point to the regulator's list as evidence of adequacy. The test becomes whether the solution works against current attacks.

Element2019 circular2026 circular
AddresseesAuthorized institutions onlyAuthorized institutions and SVF licensees
Threat namedImpersonation, stolen identities, fictitious applicationsAI automation, deepfakes, online fraud, mule-account networks
Technology examplesHolograms, security features, facial recognition, livenessNone
Robustness benchmarkAt least as robust as face-to-faceContinual updates and recalibration
Product designRisk-based CDDRisk-based design, tiering given as an example
ReviewRisk assessment before launch, then monitoringComprehensive review of existing solutions

The HKMA remote onboarding circular also gives a tiered approach as an example of risk-based product design: account features, functionality and transaction limits "scaled dynamically" according to actual usage and ongoing behaviour. Combined with "active senior management oversight", the circular says, such an approach can significantly strengthen AML/CFT controls.

What does the HKMA remote onboarding circular mean for your obligations?

The HKMA remote onboarding circular creates no new statutory duty. It changes how the HKMA will judge whether existing statutory duties, mainly under Schedule 2 of the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO), are met. Four duties are directly affected: customer due diligence on non-face-to-face customers, ongoing monitoring, suspicious transaction reporting and record-keeping. The digital identity route and governance are affected too.

Customer due diligence for customers not physically present. Section 9 of Schedule 2 is the anchor. Under paragraph 4.10.1 of the HKMA's AML/CFT Guideline for authorized institutions, a firm onboarding a customer who is not physically present should apply at least one additional measure. The options are further verification against other documents, supplementary verification of the information obtained, or a first payment from an account in the customer's name at a supervised institution. Paragraph 4.10.4 says that where a firm relies on supplementary measures, which may include using appropriate technology, it should be able to demonstrate that they "can adequately guard against impersonation risk." After this circular, that demonstration will in practice need to account for deepfakes. SVF licensees have the equivalent provision at paragraph 4.9 of their own AML/CFT Guideline.

Digital identity route. Paragraph 4.10.2 exempts a firm from the additional measures if it verified identity through a digital identification system recognised by the HKMA. The Guideline's footnote to paragraph 4.3.1 names iAM Smart as that system. The 2026 circular supersedes the 2021 letter that encouraged iAM Smart but does not mention it, and the Guideline text is unchanged. That leaves the exemption intact, but firms cannot tell whether the HKMA still wants the route promoted.

Ongoing monitoring and tiering. Section 5 of Schedule 2 requires continuous monitoring of the business relationship. The tiered model links onboarding and monitoring: limits on a remotely opened account become a monitoring control, and a request to raise them becomes a trigger for more due diligence.

Suspicious transaction reports. Section 25A of the Drug Trafficking (Recovery of Proceeds) Ordinance and the Organized and Serious Crimes Ordinance, with section 12 of the United Nations (Anti-Terrorism Measures) Ordinance, requires a report to the Joint Financial Intelligence Unit as soon as it is reasonable after knowledge or suspicion arises. Detected deepfake attempts and mule-account patterns found in the review belong in that process.

Record-keeping. Section 20 of Schedule 2 requires CDD records to be kept for at least five years after the relationship ends. Firms should keep the evidence of how each remote customer was authenticated and matched, including which version of the solution ran at the time.

DutyLegal basisWhat the circular changes
Non-face-to-face CDDAMLO Sch. 2 s.9; Guideline 4.10Evidence should in practice cover deepfake tactics
Ongoing monitoringAMLO Sch. 2 s.5Tiered limits become a monitoring control
Suspicious transaction reportsDTROP and OSCO s.25A; UNATMO s.12Deepfake and mule findings feed reporting
Record-keepingAMLO Sch. 2 s.20Keep proof of which checks ran and when
GovernanceCircular, senior management oversightComprehensive review of existing solutions

What is still uncertain?

The main uncertainties are timing, vendor accountability and the standard of effectiveness. The HKMA remote onboarding circular asks for a comprehensive review but sets no deadline or reporting format, names no technology, and gives no benchmark for what counts as effective. Firms will learn the real standard through inspections, and the first findings could arrive after products have been rebuilt.

No deadline, no template. Without a date, firms must decide how fast to act. A review completed after a thematic inspection starts will look reactive. Boards will need a documented plan with dates they set themselves.

Vendor dependence. Many authorized institutions and SVF licensees buy their document checks and face matching from third parties. The circular says nothing about outsourcing, but paragraph 4.11.2 of the Guideline treats an outsourced provider as applying CDD under the firm's own procedures and control. A firm has to show recalibration it does not directly control, so contracts need update commitments, attack-testing results and version logs.

Customer friction and financial inclusion. Tiered limits reduce money mule risk but hit legitimate new customers too. The 2019 circular cross-referred to the HKMA's 2016 circular on "De-risking and Financial Inclusion", a reminder that access matters. Firms that set starting limits too low will push customers away; limits set too high defeat the purpose.

Data held for evidence. Stronger checks tend to mean more biometric and document data retained for five years or longer. That builds the kind of central store that attracts attackers. The IDScan data breach in September 2026 showed what a stolen archive of identity scans looks like at scale.

How does Hong Kong compare with the EU and the US?

Hong Kong now sits between the EU and the US. The EBA Guidelines are the most prescriptive and expect liveness detection in unattended remote onboarding. FinCEN has issued no remote onboarding guideline comparable to the EBA's and addresses deepfakes through an alert and suspicious activity reporting. Hong Kong sets principles, names the threat and demands continual recalibration.

The European Banking Authority's Guidelines on remote customer onboarding solutions (EBA/GL/2022/15) have applied since 2 October 2023. Paragraph 41 says unattended solutions should perform liveness detection and use strong algorithms to match the customer to the document photo. In the US, FinCEN's Alert FIN-2024-Alert004 of 13 November 2024 lists deepfake red flags and asks institutions to use the key term "FIN-2024-DEEPFAKEFRAUD" in SAR filings.

JurisdictionInstrumentApproach to remote onboarding
Hong KongHKMA circular, 3 September 2026Principles, deepfakes named, continual recalibration, tiering as example
European UnionEBA/GL/2022/15, applies from 2 October 2023Prescriptive, liveness expected for unattended checks
United StatesFinCEN FIN-2024-Alert004, 13 November 2024Typologies and red flags, SAR key term, no remote-specific standard

In Hong Kong, liveness is neither required nor, on its own, proof of adequacy; the EBA expects it but lists it as one control among several. Hong Kong and the US name deepfakes; the 2022 EBA Guidelines do not.

How should compliance teams respond?

Start the HKMA remote onboarding review now and date it. Compliance teams at authorized institutions and SVF licensees should inventory every remote onboarding flow, test it against current deepfake and injection techniques, and document the results before the HKMA asks for them.

In practice, that means five steps. First, map each flow to paragraph 4.10 of the Guideline: which additional measure applies, and what evidence shows it guards against impersonation. Second, commission attack testing covering presentation attacks, injected video and synthetic documents, informed by recent deepfake identity fraud data, and record the results. Third, build intelligence from the HKMA and the police into a change log, so every recalibration traces to a threat. Fourth, define tiered limits for newly onboarded remote accounts and link limit increases to customer due diligence triggers. Fifth, review vendor contracts for update obligations and testing rights, and route confirmed deepfake attempts into suspicious transaction reporting.

Zyphe's approach reduces what an attacker can fake and what a breach can take. Identity is checked by reading the passport or ID chip over NFC to ICAO 9303 and eIDAS standards, with two-step liveness detection and no image upload. Verified data is sharded across thousands of nodes under a 29-of-100 threshold with a customer-held key, and each firm keeps an exportable audit trail. Book a demo to see how it fits your review.

The bottom line

The HKMA remote onboarding circular moves Hong Kong from illustrative technique examples to a standard of continuous effectiveness. No named technique now settles the question of adequacy. Firms need evidence that their controls work against today's deepfakes, a record of how they recalibrated, and account limits that contain the damage when a fake gets through.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

It is a letter dated 3 September 2026 from the Hong Kong Monetary Authority to all authorized institutions and stored value facility licensees. It updates expectations for opening accounts for individuals through electronic channels only, replaces the 2019 and 2021 circulars, names deepfakes as a key risk, and asks firms to comprehensively review their remote onboarding solutions.

It is supervisory guidance, not legislation. The binding duties sit mainly in Schedule 2 of the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, including section 9 on customers not physically present. The circular tells firms how the HKMA expects those duties to be met, and the HKMA can assess firms against it in inspections.

The 2026 circular names no specific technology. It keeps the identity matching principle, which requires appropriate technology to link the customer incontrovertibly to the identity provided. The 2019 circular gave facial recognition and liveness detection as illustrative, non-exhaustive examples; the 2026 text names none, so firms must show their chosen method works against current attacks.

No. The circular expects authorized institutions and SVF licensees to conduct a comprehensive review of their remote onboarding solutions, systems and oversight, using intelligence shared by the HKMA and the Hong Kong Police Force. It sets no date or reporting format, so firms should set and document their own timetable.

Not directly. It covers individual customers. The HKMA's 24 September 2020 circular on remote onboarding of corporate customers remains applicable and must be read together with the new letter, as must the 3 June 2020 feedback from thematic reviews of remote onboarding controls.

See privacy-first KYC in action

Verify identity without a central store of documents. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo